Data Processing Agreement
Between the Customer as controller and TeamTalk as processor, for personal data processed through the TeamTalk service. Drafted to contain the terms required by Article 28(3) of the UK GDPR and to satisfy the Information Commissioner's published checklist of what a controller to processor contract must set out.
Basis of this agreement
Article 28(3) of the UK GDPR requires that processing by a processor is governed by a contract that "sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller", and that stipulates the eight matters at Article 28(3)(a) to (h). Each of those eight is marked in the margin of clause 4 below. Annex 1 supplies the descriptive detail required by the opening words of Article 28(3). The Information Commissioner does not publish its own set of Article 28 standard clauses, although Article 28(8) gives it the power to; this agreement is drafted against the statutory wording and the Commissioner's checklist rather than against any approved form.
What a confirmation record is, and what it is not
The Service records that a person confirmed a notice. That is evidence of an act, not of comprehension, and it does not by itself discharge any duty under health and safety, food safety or other law. TeamTalk does not provide legal advice.
Parties and effect
| Processor | [TeamTalk Ltd], company number [number], registered office [address] ("TeamTalk") |
| Controller | [Customer legal name], company number [number], registered office [address] ("the Customer") |
| Principal agreement | The [order form / subscription agreement / pilot agreement] between the parties dated [date] (the "Principal Agreement") |
| Effective from | [date], and in any event from the date on which TeamTalk first processes personal data on the Customer's behalf |
This agreement forms part of and is subject to the Principal Agreement. Where this agreement and the Principal Agreement conflict on any matter of data protection, this agreement prevails. Where this agreement conflicts with a transfer mechanism entered into under clause 7, the transfer mechanism prevails to the extent of the conflict.
1. Definitions
"UK GDPR", "controller", "processor", "personal data", "processing", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the UK GDPR and the Data Protection Act 2018. "Data Protection Legislation" means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003 and any successor or amending legislation, including the Data (Use and Access) Act 2025. "Customer Personal Data" means personal data processed by TeamTalk on the Customer's behalf under the Principal Agreement, as described in Annex 1. "Sub-processor" means a processor engaged by TeamTalk to process Customer Personal Data. "Restricted Transfer" means a transfer of Customer Personal Data to a third country or international organisation to which Article 44A of the UK GDPR applies.
2. Roles of the parties
- The Customer is the controller and TeamTalk is the processor in respect of Customer Personal Data. The Customer determines the purposes and means of the processing; TeamTalk carries it out on the Customer's behalf.
- The Customer warrants that it has a lawful basis for the processing it instructs, that it has given the data subjects the privacy information required by Articles 13 and 14 of the UK GDPR, and that its instructions to TeamTalk will not cause TeamTalk to breach the Data Protection Legislation. TeamTalk relies on this warranty and does not assess the lawfulness of the Customer's own processing.
- TeamTalk is a controller in its own right, and this agreement does not apply, in respect of: its own personnel and business contact data; billing and account records; and security, fraud prevention and service telemetry that does not identify the Customer's workers. Where TeamTalk acts as a controller it does so under its own privacy notice at [https://team-comms.com/privacy].
- If TeamTalk determines the purposes and means of processing Customer Personal Data other than as instructed, it is a controller in respect of that processing, as Article 28(10) of the UK GDPR provides.
3. Details of the processing
The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1, as required by Article 28(3) of the UK GDPR. The parties will keep Annex 1 accurate and will update it in writing if the processing changes.
4. TeamTalk's obligations as processor
- Art 28(3)(a) Documented instructions. TeamTalk will process Customer Personal Data only on the Customer's documented instructions, including in relation to any Restricted Transfer, unless required to process by law, in which case TeamTalk will inform the Customer of that legal requirement before processing unless the law prohibits it from doing so on important grounds of public interest.
- The Customer's documented instructions are: this agreement; the Principal Agreement; the configuration options the Customer sets on its tenant; and any further written instruction the parties agree. Use of the Service by the Customer's authorised administrators is an instruction.
- TeamTalk will immediately inform the Customer if, in its opinion, an instruction infringes the UK GDPR or other Data Protection Legislation, and may suspend performance of that instruction until it is withdrawn, amended or confirmed in writing.
- If the Customer's instruction requires TeamTalk to do something outside the scope of the Service, TeamTalk may charge for the additional work at its then-current rates, having told the Customer the cost first.
- Art 28(3)(b) Confidentiality. TeamTalk will ensure that every person authorised to process Customer Personal Data has committed themselves to confidentiality or is under an appropriate statutory obligation of confidentiality. Those commitments survive the end of the individual's engagement. Access is limited to personnel who need it to provide the Service or to comply with law, and each such person receives data protection and security briefing on joining and at least annually.
- Art 28(3)(c) Security. TeamTalk will take all measures required by Article 32 of the UK GDPR. Taking account of the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the risk to data subjects, TeamTalk implements and maintains the technical and organisational measures set out in Annex 2. TeamTalk may update those measures, but not so as to reduce the overall level of security, and will publish the current version at [https://team-comms.com/security].
- Art 28(3)(d)Art 28(2)Art 28(4) Sub-processors.
- The Customer gives TeamTalk general written authorisation to engage the Sub-processors listed in Annex 3, and to engage further Sub-processors in accordance with this clause.
- TeamTalk will inform the Customer in writing of any intended addition or replacement of a Sub-processor at least 30 days before that Sub-processor begins processing, by email to the Customer's notice address and by updating the list published at [https://team-comms.com/sub-processors]. The Customer may subscribe to notification of changes to that page.
- Right to object. The Customer may object to a new or replacement Sub-processor on reasonable data protection grounds by written notice within 30 days of being informed. The parties will discuss the objection in good faith. If TeamTalk cannot, within 30 days of the objection, offer a reasonable alternative or a change that resolves the objection, the Customer may terminate the Principal Agreement, without penalty, on 30 days' written notice, with a pro rata refund of fees paid for the unexpired period of the then-current term. That is the Customer's sole remedy for an objection under this clause.
- TeamTalk will impose on each Sub-processor, by written contract, the same data protection obligations as are set out in this agreement, in particular the obligation to provide sufficient guarantees to implement appropriate technical and organisational measures. Where a Sub-processor fails to fulfil its data protection obligations, TeamTalk remains fully liable to the Customer for the performance of that Sub-processor's obligations.
- TeamTalk will make available to the Customer, on request, the data protection terms of its contract with any Sub-processor, redacted only as necessary to protect commercially confidential information.
- An emergency replacement of a Sub-processor required to maintain the security or availability of the Service may be made on shorter notice, with the reasons given to the Customer in writing at the time and the objection right in clause 4.4.3 preserved.
- Art 28(3)(e) Assistance with data subject rights. Taking into account the nature of the processing, TeamTalk will assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to requests to exercise the rights in Chapter III of the UK GDPR, being the rights of access, rectification, erasure, restriction, portability and objection, and rights relating to automated decision-making.
- The Service allows the Customer's administrators to locate, view, correct, export and delete an individual worker's record without TeamTalk's involvement. Where the Customer needs further help, TeamTalk will respond within [5] working days of a written request.
- If a data subject contacts TeamTalk directly about Customer Personal Data, TeamTalk will not respond substantively but will forward the request to the Customer without undue delay and tell the data subject that it has done so.
- Assistance under this clause is provided at no charge unless the volume or complexity of requests is materially beyond the ordinary operation of the Service, in which case TeamTalk may charge its reasonable costs, notified in advance.
- Art 28(3)(f) Assistance with Articles 32 to 36. Taking into account the nature of the processing and the information available to it, TeamTalk will assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 of the UK GDPR, being security of processing, notification of personal data breaches to the Information Commissioner and to data subjects, data protection impact assessments and prior consultation. TeamTalk maintains a pre-completed data protection impact assessment pack describing the Service, which it will supply on request to assist the Customer's own assessment. The Customer remains responsible for carrying out and recording its own assessment.
- Art 28(3)(g) Retention, deletion and return. At the choice of the Customer, TeamTalk will delete or return all Customer Personal Data after the end of the provision of services relating to processing, and will delete existing copies unless required by law to store them.
- Unless the Customer instructs otherwise in writing before the end of the period, TeamTalk will make Customer Personal Data available for export in a machine-readable format for 30 days after the end of the Principal Agreement, and will then delete it within a further 30 days.
- Customer Personal Data present in encrypted backups is not restored into the live environment and is deleted when the backup expires, within [30] days. Until then it remains subject to this agreement, including the security measures in Annex 2.
- TeamTalk will confirm deletion in writing on request.
- Where TeamTalk is required by law to retain Customer Personal Data, it will inform the Customer of the requirement, retain only what the law requires, and continue to protect it under this agreement.
- Retention during the term. While the Principal Agreement is in force, TeamTalk applies the retention periods below. They are [defaults; the Controller may instruct otherwise] in writing, and the instruction is recorded in Annex 1. Where the Controller instructs a longer period, it remains responsible for the storage limitation principle in Article 5(1)(e) of the UK GDPR.
| Category | Default retention | Then |
| Posts, comments, translations, and confirmation records (including briefing record exports) | 24 months after the end of the relationship with the Controller | Deleted automatically |
| Worker accounts and profile data | Deactivated on the recorded leaving date; identifiers minimised 12 months after that date | Name and mobile number removed; the confirmation record is retained in minimised form for the period above so the Controller keeps a countable record |
| Hazard reports and hazard photographs | 24 months | Deleted automatically |
| Application, access and audit logs, including the impersonation log | 90 days | Rotated and deleted |
| Encrypted backups | [30] days | Aged out; never restored into the live environment |
- Art 28(3)(h) Information and audits. TeamTalk will make available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28, and allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer.
- TeamTalk will satisfy this obligation in the first instance by supplying its current security summary, its sub-processor list, its policies, its answers to the Customer's information security questionnaire and, once held, its Cyber Essentials certificate. Cyber Essentials: not currently held. Assessment booked with [body], target [date].
- If that is not sufficient, the Customer may audit TeamTalk's processing, in person or remotely, once in any 12-month period on at least 30 days' written notice, during normal business hours, for no longer than [two] working days, and subject to confidentiality undertakings. The Customer will minimise disruption and will not access the personal data or confidential information of any other TeamTalk customer.
- The Customer may audit more frequently, and on shorter notice, where required to do so by a supervisory authority or following a personal data breach affecting Customer Personal Data.
- Each party bears its own costs. The Customer will pay TeamTalk's reasonable costs of an audit that goes beyond one audit in any 12-month period, unless the audit reveals a material breach by TeamTalk.
- Nothing in this clause limits the Customer's or a supervisory authority's statutory rights.
5. Personal data breaches
- TeamTalk will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, as Article 33(2) of the UK GDPR requires. TeamTalk commits to notifying the Customer within 24 hours of becoming aware, so that the Customer has time to meet its own obligation under Article 33(1) to notify the Information Commissioner without undue delay and, where feasible, not later than 72 hours after it becomes aware.
- The notification will be sent to the Customer's notice address in Annex 1 and will describe, so far as known at the time: the nature of the breach including, where possible, the categories and approximate number of data subjects and of records concerned; the name and contact details of TeamTalk's contact point; the likely consequences; and the measures taken or proposed to address the breach and mitigate its effects. Where the information is not all available at once, TeamTalk will provide it in phases without further undue delay.
- TeamTalk will take all reasonable steps to contain, investigate and remediate the breach, will preserve evidence, and will provide a written post-incident report within [10] working days of containment.
- TeamTalk will assist the Customer in communicating the breach to data subjects under Article 34 where the Customer decides that is required.
- TeamTalk will not notify the Information Commissioner or any data subject on the Customer's behalf, and will not make any public statement identifying the Customer, unless the Customer instructs it to in writing or TeamTalk is required to by law. Nothing in this clause prevents TeamTalk from meeting its own legal obligations as a controller.
6. Records
TeamTalk maintains a record of all categories of processing carried out on behalf of the Customer, in accordance with Article 30(2) of the UK GDPR, and will make it available to the Customer or to the Information Commissioner on request.
7. International transfers
Note on the law as it now stands
Chapter V of the UK GDPR was substantially rewritten with effect from 5 February 2026 by section 85 of and Schedule 7 to the Data (Use and Access) Act 2025, commenced by SI 2026/82. Articles 44 and 45 were omitted and replaced by new Articles 44A, 45A, 45B and 45C, and Article 46 was amended. Sections 17A to 18 of the Data Protection Act 2018 were repealed, with existing adequacy regulations preserved and treated as made under Article 45A. Any transfer clause, transfer risk assessment or supplier questionnaire answer drafted before that date and citing Article 45 or section 17A is citing repealed provisions and must be refreshed.
- Hosting location. TeamTalk hosts the Service, and stores all Customer Personal Data at rest, in the United Kingdom (AWS London, eu-west-2). This is a commitment under this agreement, not a configuration preference, and TeamTalk will not move the hosting region without the Customer's prior written agreement.
- TeamTalk will not make a Restricted Transfer of Customer Personal Data except in accordance with this clause, which is the Customer's documented instruction on transfers for the purposes of Article 28(3)(a).
- The Customer authorises the Restricted Transfers described in Annex 3. TeamTalk will ensure that each is made on one of the bases permitted by Article 44A(2) of the UK GDPR, namely that it is approved by regulations under Article 45A, is made subject to appropriate safeguards under Article 46, or falls within a derogation under Article 49.
- Transfers to Twilio and to Mux are made in reliance on the UK Extension to the EU–US Data Privacy Framework, given effect by the Data Protection (Adequacy) (United States of America) Regulations 2023 (SI 2023/1028), in force 12 October 2023, which are preserved by paragraph 26 of Part 2 of Schedule 9 to the Data (Use and Access) Act 2025 and now take effect as regulations under Article 45A. Neither a transfer risk assessment nor a separate transfer agreement is required for a transfer to an entity actively certified under the UK Extension for the relevant data. TeamTalk will verify, at least every six months and before relying on this route, that the receiving legal entity remains actively certified for the UK Extension on the Data Privacy Framework List, and will move the transfer to the Article 46 route in clause 7.5 if it is not. Checked 28 August 2026: Twilio Inc. is listed Active for the UK Extension; Mux is listed Active, re-certification under review, which is the one status in this agreement that can lapse, so it is re-checked before each questionnaire answer and before each renewal. TeamTalk notes that the UK adequacy regulations are independent of the European Commission's own adequacy decision for the United States, so a challenge to the latter would not automatically end this route.
- Transfers to OpenAI OpCo, LLC are not covered by the Data Privacy Framework, under which OpenAI holds no certification. They are made subject to appropriate safeguards under Article 46, using the International Data Transfer Addendum to the European Commission's Standard Contractual Clauses (version B1.0), or the International Data Transfer Agreement (version A1.0), each issued by the Information Commissioner under section 119A of the Data Protection Act 2018, laid before Parliament on 2 February 2022 and in force from 21 March 2022. OpenAI's own data processing addendum adopts the Addendum route for United Kingdom data. TeamTalk holds a documented transfer risk assessment for that transfer, carried out against the test in Article 46(6), namely whether the standard of protection provided for the data subject after the transfer would not be materially lower than the standard provided under the UK GDPR and the Data Protection Act 2018, taken as a whole. TeamTalk will provide the assessment to the Customer on request and will review it at least annually and on any material change.
- Transfer minimisation. As a design measure: Post text, comment text, direct message text and hazard report text are sent for translation. No names, phone numbers or identifiers accompany the text. The Customer is responsible for the content it publishes and should not name identifiable individuals in text that will be translated. All Customer Personal Data at rest remains in the United Kingdom. OpenAI retains application programming interface inputs and outputs for up to 30 days for abuse monitoring and does not use them to train its models.
- If a transfer mechanism relied on under this clause is invalidated, suspended or withdrawn, TeamTalk will inform the Customer without undue delay and will, at its option, adopt an alternative lawful mechanism, apply supplementary measures, or cease the transfer and the affected feature.
8. Liability
The parties' liability under this agreement is governed by, and subject to, the limitations and exclusions of liability in the Principal Agreement, which apply to this agreement as if set out here in full, and the caps in the Principal Agreement apply in aggregate across both agreements rather than separately to each. Nothing in this agreement or in the Principal Agreement limits or excludes a data subject's rights under the Data Protection Legislation, either party's liability to a supervisory authority, or any liability that cannot lawfully be limited or excluded. Where a claim is made against both parties by a data subject or a supervisory authority, each will bear the share of responsibility attributable to it under Article 82 of the UK GDPR.
9. Term, and general
- This agreement takes effect on the date stated above and continues for as long as TeamTalk processes Customer Personal Data, and thereafter to the extent of clauses that by their nature survive, including clauses 4.2, 4.7, 4.8, 5 and 8.
- TeamTalk may update this agreement on 30 days' written notice where required by a change in law, in guidance from the Information Commissioner, or in the Service. No update may reduce the protections given to Customer Personal Data. If an update does so in the Customer's reasonable opinion, the Customer may object under the process in clause 4.4.3.
- This agreement is in writing, including in electronic form, as Article 28(9) of the UK GDPR requires. It may be signed in counterparts and by electronic signature.
- This agreement is governed by the law of England and Wales and the parties submit to the exclusive jurisdiction of the courts of England and Wales, without prejudice to any mandatory jurisdiction under the Data Protection Legislation.
Annex 1 · Details of the processing
Supplied as required by the opening words of Article 28(3) of the UK GDPR and by the Information Commissioner's contracts checklist.
| Subject matter | The provision of the TeamTalk service: delivery of workplace notices, safety briefings and messages to the Customer's frontline workforce, translated into each recipient's chosen language, with recorded confirmation of receipt and an exportable record of who was told what and when. |
| Duration | The term of the Principal Agreement, plus the export and deletion periods in clause 4.7 (30 days for export, then deletion within a further 30 days, with backups aged out within [30] days). |
| Nature of the processing | Collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, machine translation, transmission and dissemination, restriction, erasure and destruction; carried out by automated means on hosted infrastructure. |
| Purpose of the processing | To enable the Customer to communicate with its workforce, to record and evidence that individual workers have received and confirmed mandatory notices, to allow workers to report hazards, and to assist the Customer in discharging its own statutory duties to provide comprehensible information, instruction and training. Processing is carried out solely for the Customer's purposes and not for any purpose of TeamTalk's own. |
| Types of personal data |
Identity and contact: first and last name; mobile telephone number; email address (optional); employee or payroll reference (optional).
Profile: preferred language; job role or trade (optional); employer or subcontractor name; site, depot or team; user group membership; role within the tenant (administrator, moderator, worker); start date and leaving date.
Content: the text of posts, comments and direct messages authored by or addressed to the individual, and machine translations of that text; video and audio uploaded by the Customer, including captions; hazard reports, including free text, a location and photographs, which may incidentally show identifiable individuals.
Usage and confirmation records: sign-in events and timestamps; confirmations of receipt of mandatory posts, with timestamps; read and delivery status; device and browser type; IP address; push notification subscription tokens.
Special category data (Article 9): The Service is not designed for special category data. It may arise incidentally in free text (for example accident notices or dietary/religious information in a canteen notice). The Controller is responsible for the lawful basis for any such data; the Annex 2 measures apply to all Customer Data without distinction. Where the Controller foresees that a notice will carry Article 9 data, it must identify both a lawful basis under Article 6 and a condition under Article 9(2), together with any further condition in Schedule 1 to the Data Protection Act 2018, and record them. Preferred language is collected to deliver translation and is not used or inferred as a proxy for nationality or ethnicity.
Criminal offence data (Article 10) is a different regime and is not the same thing as Article 9 data: processing personal data relating to criminal convictions, offences or related security measures is permitted only under the control of official authority or where authorised by domestic law providing appropriate safeguards, and in the United Kingdom that means a condition in Schedule 1 to the Data Protection Act 2018. The Service must not be used for criminal offence data, and TeamTalk offers no field for it. |
| Categories of data subjects | The Customer's employees; workers and agency staff engaged by or through the Customer; employees and operatives of subcontractors working at the Customer's sites or on the Customer's contracts; the Customer's managers, supervisors and administrators who use the Service to publish and to monitor; and, incidentally, any individual appearing in a photograph attached to a hazard report or in video content published by the Customer. |
| Frequency | Continuous for the duration of the Principal Agreement. |
| Monitoring | Per-worker sign-in timestamps, confirmation records and chase lists are monitoring of workers within the meaning of the Information Commissioner's employment practices guidance. The Controller is responsible for the lawful basis, the transparency information and the proportionality assessment. TeamTalk supplies a pre-completed DPIA and monitoring pack, and a worker privacy notice template, to assist. TeamTalk does not provide location tracking, message-content analysis or productivity scoring, and the Service has no such feature. |
| Retention instruction | The defaults in clause 4.7.5 apply unless the Controller states otherwise here: [state any different period, per category] |
Obligations and rights of the Controller Art 28(3) | Stated here because the opening words of Article 28(3) require the contract to set them out. The Controller:
- determines the purposes and means of the processing, and gives TeamTalk documented instructions under clause 4.1;
- is responsible for establishing and recording a lawful basis under Article 6, and any Article 9(2) condition, for the personal data it uploads and publishes;
- is responsible for giving workers the privacy information required by Articles 13 and 14, including about the monitoring described above, and for consulting workers or their representatives where the Commissioner's guidance expects it;
- warrants the accuracy and currency of the worker list, including leaving dates, and is responsible for correcting it;
- is responsible for responding to data subject rights requests under Chapter III, using the tools in the Service, with TeamTalk assisting under clause 4.5;
- decides whether a DPIA is required under Article 35 and carries it out, with TeamTalk assisting under clause 4.6;
- decides whether to notify the Commissioner or data subjects of a personal data breach under Articles 33 and 34;
- is entitled to the information and audit rights in clause 4.8, to the sub-processor notice and objection rights in clause 4.4, to the deletion or return of Customer Personal Data under clause 4.7, and to terminate under clause 4.4.3;
- may instruct retention periods different from the clause 4.7.5 defaults, and must not instruct anything that would put TeamTalk in breach of the Data Protection Legislation;
- is responsible for the content it publishes, including the decision to rely on machine translation for any safety-critical wording.
|
| Customer contact for data protection | Name [name] · role [role] · email [email] · telephone [number]. This is the address for breach notification under clause 5.2. |
| TeamTalk contact for data protection | Name [name] · email [privacy@team-comms.com] · telephone [number]. TeamTalk is not required to appoint a data protection officer under Article 37 of the UK GDPR and has not appointed one; this is the responsible named individual. |
| ICO registration | TeamTalk is registered with the Information Commissioner under registration number [number] and pays the annual data protection fee (tier 1, micro organisations, £52, or £47 by direct debit). |
Annex 2 · Technical and organisational measures
The measures TeamTalk implements under clause 4.3 and Article 32 of the UK GDPR. Values in [square brackets] are confirmed per deployment. The full security summary is a separate document and forms part of this annex.
| Measure | Implementation |
| Pseudonymisation and encryption Art 32(1)(a) | TLS 1.2 or above for all data in transit, with automatically renewed certificates and HTTP redirected to HTTPS. AES-256 encryption at rest on Amazon EBS volumes and Amazon S3 objects, including backups. Administrator passwords stored only as bcrypt hashes. Uploaded files served through short-lived signed URLs and never publicly listable. Only post content, and no identifiers, is sent to the translation sub-processor. |
| Confidentiality Art 32(1)(b) | Logical tenant isolation enforced at the data layer, with automated cross-tenant tests not yet: every record carries a tenant identifier and every query is scoped to the tenant resolved from the request domain, enforced globally rather than query by query. The Service is multi-tenant; it is not single-tenant, and TeamTalk does not describe it as such. Role-based access within each tenant (administrator, moderator, worker). Sign-in by one-time code to a verified mobile number, with no worker password to phish or reuse. This is single-factor possession, not multi-factor authentication, and TeamTalk does not describe it as MFA. Session lifetime, device binding and invalidation on a change of mobile number are [planned before first customer]. Access revoked automatically, including mid-session, on a worker's recorded leaving date. Support impersonation is restricted to named TeamTalk personnel and every use is logged with operator, subject, tenant and timestamp. TeamTalk staff access to production uses individual named accounts, SSH keys and multi-factor authentication, on the principle of least privilege, with administrative accounts kept separate from day-to-day accounts and access reviewed [quarterly]. |
| Integrity Art 32(1)(b) | Framework-level protection against SQL injection, cross-site scripting and cross-site request forgery, not disabled. Audit logging of administrator actions, impersonation, account creation and deletion, leaving-date changes, and publication and deletion of posts. Changes deployed from a protected branch under source control. |
| Availability and resilience Art 32(1)(b) | Hosted in the United Kingdom (AWS London, eu-west-2), as clause 7.1 commits. Uptime and error monitoring with alerting to the named director by email and SMS. There is no on-call engineer and no 24/7 rota; the security contact is monitored [08:00 to 18:00 UK, Monday to Friday]. Databases and caches not reachable from the public internet; only HTTPS and restricted SSH exposed. Infrastructure reproducible through Laravel Forge. |
| Restoration Art 32(1)(c) | Encrypted database backups taken [daily] and retained [30] days in the same UK region. Object storage versioned. Recovery time objective [4] hours; recovery point objective [24] hours. |
| Testing and review Art 32(1)(d) | Restore to a scratch environment tested [quarterly] with the date and outcome recorded. Dependencies reviewed and updated [monthly] with automated vulnerability alerting. Operating system and application updates for vulnerabilities rated critical or high, or with a CVSS v3 base score of 7 or above, applied within 14 days of release, which is the Cyber Essentials requirement. Unsupported software removed or upgraded. [Independent penetration test carried out by [supplier] on [date].] |
| Organisational | As at [date] TeamTalk has one director and no employees, so the personnel measures below apply to the director today and to each person engaged from the day they are engaged: written confidentiality obligations surviving engagement; right to work check before starting; security and data protection briefing on joining and at least annually; all access removed on the last working day. Written incident response procedure with a single named owner. Information security policy aligned to the five Cyber Essentials technical control areas. |
| Certification | Cyber Essentials: not currently held. Assessment booked with [body], target [date]. TeamTalk is not certified to ISO/IEC 27001; a written information security management roadmap is available on request. TeamTalk does not claim certification it does not hold. |
Annex 3 · Authorised sub-processors
Authorised under clause 4.4.1. The current list is published at [https://team-comms.com/sub-processors] and the two are versioned together. Changes are notified at least 30 days in advance and may be objected to under clause 4.4.3. Every Data Privacy Framework status below was checked against the official participant list at dataprivacyframework.gov/list on 28 August 2026. Certifications lapse, so TeamTalk re-checks every status every six months and before answering any supplier questionnaire.
| Sub-processor and contracting entity | Processing carried out | Personal data received | Country of processing | Transfer basis under Chapter V, checked 28 Aug 2026 |
Amazon Web Services Contracting entity [AWS EMEA SARL] | Hosting of the application, database, object storage of files and photographs, and encrypted backups | All Customer Personal Data described in Annex 1 | United Kingdom (AWS London, eu-west-2) | No transfer for hosting. Data at rest stays in the United Kingdom; the region is contractually controlled and AWS will not move or replicate content outside it without agreement. Support access from outside the UK runs under Article 46 on the AWS UK GDPR addendum, which incorporates the ICO's International Data Transfer Addendum. AWS's own contract documents make no Data Privacy Framework claim, so the addendum, not the data bridge, is the operative route. (Amazon.com, Inc. is separately listed Active for the UK Extension; that listing is not what AWS contracts on.) |
Twilio Inc. Twilio Verify and Programmable Messaging | Delivery of one-time codes for sign-in, and delivery of posts by SMS where the Customer enables it | Mobile telephone number; message text where SMS delivery of posts is enabled | United States | Article 45A, UK Extension to the EU–US Data Privacy Framework. Twilio Inc. listed Active for the UK Extension, checked 28 Aug 2026, non-HR data. No transfer agreement and no transfer risk assessment required. Twilio's addendum falls back to the ICO Addendum if the certification is withdrawn. |
| Mux, Inc. | Video ingest, encoding, storage, delivery and automatic caption generation | Video and audio content published by the Customer, which may show or identify individuals | United States | Article 45A, UK Extension. Mux listed Active, re-certification under review at 28 Aug 2026. Said plainly because it can lapse: this is the one route in this annex that needs watching, and TeamTalk will move the transfer to the ICO Addendum, which is Mux's own contractual fallback, if the status changes. |
| OpenAI OpCo, LLC | Machine translation of post text, comment text, direct message text, hazard report text and video captions | Text only. Post text, comment text, direct message text and hazard report text are sent for translation. No names, phone numbers or identifiers accompany the text. | United States | No Data Privacy Framework certification: 0 records of 7,567 on the participant list, checked 28 Aug 2026. Transfer runs on Article 46, via the ICO's International Data Transfer Addendum (version B1.0) to the EU Standard Contractual Clauses, or the IDTA (version A1.0), supported by a documented transfer risk assessment against the Article 46(6) "not materially lower" test. OpenAI's own data processing addendum adopts the Addendum route for United Kingdom data. |
Transactional email [Amazon SES / Mailgun, confirm which] | Delivery of transactional email to the Customer's administrators | Email address, name, message content | [United Kingdom if Amazon SES in eu-west-2 / United States if Mailgun] | [Confirm which is configured before issuing.] Amazon SES in eu-west-2 is covered by the AWS UK GDPR addendum under Article 46 and involves no transfer for data at rest. Mailgun Technologies, Inc. is listed Active for the UK Extension, checked 28 Aug 2026, so Article 45A applies, but only to that entity: another Sinch group entity is not covered by it. |
Real-time delivery [self-hosted Reverb; Pusher only if enabled] | Real-time delivery of updates to the browser | Message payloads and channel identifiers | [United Kingdom, on TeamTalk's own servers, if Reverb] | Where Laravel Reverb is self-hosted there is no sub-processor and no transfer: the WebSocket server runs on TeamTalk's own UK infrastructure and no third party sees message content. Pusher is engaged only if it is enabled; Pusher does not appear on the Data Privacy Framework list (checked 28 Aug 2026), so if it is enabled the basis must be stated here before it processes anything. [Delete this row if Reverb is self-hosted.] |
Error and uptime monitoring [provider, confirm which] | Capture of application errors and availability monitoring | Potentially IP address, user identifier and request context contained in an error report | [region] | [State the basis, or record in writing that the tool stores no request payloads and is therefore not a sub-processor.] |
Not sub-processors. Laravel Forge is used to provision and configure servers and holds deployment credentials, but does not store or process Customer Personal Data.
Signed for the Customer (controller)
Signature
Name and title
Date
Signed for TeamTalk (processor)
Signature
Name and title
Date
Internal checklist · remove this page before issuing the agreement
This page is for TeamTalk, not for the customer
The agreement above is drafted to be signed as it stands once the bracketed values are filled in. These are the points that must be confirmed against the live deployment and the live certification position before the agreement is sent to anyone. The build produces two files: data-processing-agreement-ISSUE.pdf, which does not contain this page and is the one you send, and data-processing-agreement-INTERNAL.pdf, which does. Send the ISSUE file.
- Cyber Essentials. Book the assessment, fill in the body and the target date in clause 4.8.1 and Annex 2, and replace the "not currently held" wording only on the day the certificate is issued.
- Insurance. Bind the cyber policy, then write its limit into pilot agreement clause 14.3 and Schedule 1. The data-protection super-cap is set to that limit, so the limit must exist before the agreement is issued.
- Confirm the Customer has not configured free-text fields that invite health data, for example return-to-work notices, and record the Annex 1 special-category position with them
- Confirm no Article 37 trigger applies as the business grows
- RTO, RPO, backup frequency and retention, and whether the clause 4.7.5 retention defaults have been varied by the Controller
- Date and supplier of the most recent penetration test and restore test
- Confirm the AWS contracting entity and the current AWS DPA version
- Confirm the executed IDTA or Addendum for OpenAI is on file and the transfer risk assessment is dated within 12 months
- Re-check every Data Privacy Framework status every six months, and always before answering a questionnaire. Mux is the one to watch: "Active, re-certification under review" at 28 August 2026
- Whether Pusher is in use at all, the cluster region and the contracting entity; if Reverb is self-hosted, delete that row from Annex 3 and from the security summary
- Which email provider, which contracting entity and which sending region is configured; a Sinch group entity other than Mailgun Technologies, Inc. is not covered by that certification
- If the monitoring tool captures request payloads it is a sub-processor and must be listed in Annex 3; if it does not, record that finding in writing
- Confirm Laravel Forge remains outside the sub-processor list; if Forge holds database credentials that permit access to personal data, take a view with the solicitor
- Write the automated cross-tenant isolation tests, then delete the "not yet" marker in Annex 2. Do not delete it before the tests exist
- Confirm the sub-processor page at the published URL matches Annex 3 exactly, and that the two are versioned together
- Confirm the solicitor's review has been completed and record the date and the version reviewed